From f285b2dff7b8e035cfd241016770c0de61519048 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?David=20Barrag=C3=A1n=20Merino?= Date: Tue, 29 Sep 2026 20:06:15 +0200 Subject: [PATCH] :construction_worker: Add actionlint and zizmor checks for workflows MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: David Barragán Merino --- .github/actionlint.yaml | 14 ++ .github/workflows/build-bundle.yml | 1 - .../workflows/build-docker-admin-console.yml | 2 +- .github/workflows/build-docker.yml | 1 - .github/workflows/lint-workflows.yml | 78 +++++++++++ .github/workflows/plugins-deploy-package.yml | 1 - .github/zizmor.yml | 123 ++++++++++++++++++ 7 files changed, 216 insertions(+), 4 deletions(-) create mode 100644 .github/actionlint.yaml create mode 100644 .github/workflows/lint-workflows.yml create mode 100644 .github/zizmor.yml diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml new file mode 100644 index 0000000000..166202b6e3 --- /dev/null +++ b/.github/actionlint.yaml @@ -0,0 +1,14 @@ +# actionlint configuration — https://github.com/rhysd/actionlint/blob/main/docs/config.md +self-hosted-runner: + labels: + - penpot-standar-runner + - penpot-extended-runner + +paths: + .github/workflows/**/*.{yml,yaml}: + ignore: + # shellcheck style/info notices that are pervasive in the existing + # scripts (unquoted `>> $GITHUB_OUTPUT`, repeated redirects). Real + # shellcheck warnings and errors are still reported. + - 'SC2086:info' + - 'SC2129:style' diff --git a/.github/workflows/build-bundle.yml b/.github/workflows/build-bundle.yml index 8db99ea68c..43ce74c1b6 100644 --- a/.github/workflows/build-bundle.yml +++ b/.github/workflows/build-bundle.yml @@ -20,7 +20,6 @@ on: description: 'Name of the branch or ref' type: string required: true - default: 'develop' force: description: 'Rebuild and overwrite even if this version already exists in S3' type: boolean diff --git a/.github/workflows/build-docker-admin-console.yml b/.github/workflows/build-docker-admin-console.yml index 4c11db6fba..e193d47704 100644 --- a/.github/workflows/build-docker-admin-console.yml +++ b/.github/workflows/build-docker-admin-console.yml @@ -64,7 +64,7 @@ jobs: # Locate the dispatched run using the correlation id embedded in its run-name RUN_ID="" - for i in $(seq 1 24); do + for _ in $(seq 1 24); do sleep 5 RUN_ID=$(gh run list --repo "$REPO" --workflow "$WORKFLOW" \ --limit 10 --json databaseId,displayTitle \ diff --git a/.github/workflows/build-docker.yml b/.github/workflows/build-docker.yml index 9c86d6ea5d..271042700a 100644 --- a/.github/workflows/build-docker.yml +++ b/.github/workflows/build-docker.yml @@ -19,7 +19,6 @@ on: description: 'Name of the branch or ref' type: string required: true - default: 'develop' sha: description: >- Exact commit to check out (full 40-char SHA, e.g. from diff --git a/.github/workflows/lint-workflows.yml b/.github/workflows/lint-workflows.yml new file mode 100644 index 0000000000..23f9849899 --- /dev/null +++ b/.github/workflows/lint-workflows.yml @@ -0,0 +1,78 @@ +name: "CI: Workflows" + +# Static analysis of the GitHub Actions workflows themselves: +# - actionlint: syntax, expressions, runner labels, job/step references, +# and shellcheck on every `run:` block. +# - zizmor: security audits (template injection, dangerous triggers, +# credential persistence, ...). Configured in .github/zizmor.yml. + +on: + pull_request: + types: [opened, synchronize, reopened, ready_for_review] + paths: + - '.github/workflows/**' + - '.github/actions/**' + - '.github/actionlint.yaml' + - '.github/zizmor.yml' + push: + branches: + - develop + - staging + - main + paths: + - '.github/workflows/**' + - '.github/actions/**' + - '.github/actionlint.yaml' + - '.github/zizmor.yml' + workflow_dispatch: + +concurrency: + group: lint-workflows-${{ github.ref }} + cancel-in-progress: true + +permissions: {} + +env: + ACTIONLINT_VERSION: '1.7.12' + ZIZMOR_VERSION: '1.30.1' + +jobs: + lint: + name: Lint workflows + if: ${{ !github.event.pull_request.draft }} + # PR code is untrusted: never run this on the self-hosted runners. + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + contents: read + + steps: + - name: Checkout + uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 + with: + persist-credentials: false + + - name: Install actionlint + run: | + curl -fsSL --retry 3 \ + "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" \ + | tar -xz -C "$RUNNER_TEMP" actionlint + echo "$RUNNER_TEMP" >> "$GITHUB_PATH" + + # Each finding is emitted as a `::error` annotation on the PR diff. + - name: Run actionlint + run: | + # shellcheck disable=SC2016 # Go template, not shell expansion. + actionlint -format '{{range $err := .}}::error file={{$err.Filepath}},line={{$err.Line}},col={{$err.Column}},title=actionlint ({{$err.Kind}})::{{$err.Message}}\n{{end}}' + + - name: Run zizmor + if: ${{ !cancelled() }} + env: + # Enables the online audits (known-vulnerable-actions, + # impostor-commit, ref-confusion, ...). + GH_TOKEN: ${{ github.token }} + run: | + pipx run "zizmor==${ZIZMOR_VERSION}" \ + --config .github/zizmor.yml \ + --format github \ + .github/workflows diff --git a/.github/workflows/plugins-deploy-package.yml b/.github/workflows/plugins-deploy-package.yml index 8a65ef686f..eec741a009 100644 --- a/.github/workflows/plugins-deploy-package.yml +++ b/.github/workflows/plugins-deploy-package.yml @@ -23,7 +23,6 @@ on: description: 'Name of the branch' type: string required: true - default: 'develop' plugin_name: description: 'Publig name (from plugins/apps/-plugin)' type: string diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000000..bdaa8777e5 --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,123 @@ +# zizmor configuration — https://docs.zizmor.sh/configuration/ +# +# Every audit is enforced for every workflow. The per-file ignores below are +# the findings that already existed when this check was introduced: each one +# is a pending clean-up, not an accepted risk. New workflows are checked +# with no exceptions. Remove a file from a list in the same PR that fixes it, +# and the whole rule entry once its list is empty. +rules: + # Avoid installing packages ad hoc inside `run:`. + adhoc-packages: + ignore: + - plugins-deploy-api-doc.yml + - plugins-deploy-package.yml + - plugins-deploy-styles-doc.yml + # Use `persist-credentials: false` in actions/checkout. + artipacked: + ignore: + - build-bundle.yml + - build-docker-devenv.yml + - build-docker.yml + - plugins-deploy-api-doc.yml + - plugins-deploy-package.yml + - plugins-deploy-packages.yml + - plugins-deploy-styles-doc.yml + - release.yml + - tests-backend.yml + - tests-common.yml + - tests-e2e.yml + - tests-exporter.yml + - tests-frontend.yml + - tests-library.yml + - tests-mcp.yml + - tests-plugins.yml + - tests-wasm.yml + # Avoid restoring caches in release/publish workflows. + cache-poisoning: + ignore: + - plugins-deploy-api-doc.yml + - plugins-deploy-styles-doc.yml + # Review `pull_request_target` usage. + dangerous-triggers: + ignore: + - auto-label.yml + - commit-checker.yml + # Declare least-privilege `permissions:` per workflow/job. + excessive-permissions: + ignore: + - auto-label.yml + - build-adhoc.yml + - build-bundle.yml + - build-develop.yml + - build-docker-admin-console.yml + - build-docker-devenv.yml + - build-docker.yml + - build-staging.yml + - build-tag.yml + - build-tmp-tokens.yml + - commit-checker.yml + - plugins-deploy-packages.yml + - tests-backend.yml + - tests-common.yml + - tests-e2e.yml + - tests-exporter.yml + - tests-frontend.yml + - tests-library.yml + - tests-mcp.yml + - tests-plugins.yml + - tests-wasm.yml + # Scope GitHub App tokens. + github-app: + ignore: + - auto-label.yml + # Pass only the secrets each reusable workflow needs. + secrets-inherit: + ignore: + - build-adhoc.yml + - build-develop.yml + - build-staging.yml + - build-tag.yml + - build-tmp-tokens.yml + - plugins-deploy-packages.yml + # Style nudge towards the `$/...` syntax; not worth enforcing. + self-repository: + disable: true + # Replace actions that duplicate built-in runner tools. + superfluous-actions: + ignore: + - release.yml + # Pin container images to a digest. + unpinned-images: + ignore: + - plugins-deploy-package.yml + - tests-backend.yml + - tests-common.yml + - tests-e2e.yml + - tests-exporter.yml + - tests-frontend.yml + - tests-library.yml + - tests-mcp.yml + - tests-plugins.yml + - tests-wasm.yml + # Pin actions to a full commit SHA. + unpinned-uses: + ignore: + - auto-label.yml + - build-bundle.yml + - build-docker-devenv.yml + - build-docker.yml + - commit-checker.yml + - plugins-deploy-api-doc.yml + - plugins-deploy-package.yml + - plugins-deploy-packages.yml + - plugins-deploy-styles-doc.yml + - release.yml + - tests-backend.yml + - tests-common.yml + - tests-e2e.yml + - tests-exporter.yml + - tests-frontend.yml + - tests-library.yml + - tests-mcp.yml + - tests-plugins.yml + - tests-wasm.yml